Solid OIDC Security Consideration Client Secrets
Nobody has claimed this yet.
- Dominant language
- Bikeshed
- Stars
- 26
- Forks
- 14
- PR merge metrics
- No merged PRs in 30d
Description
In #security-client-secrets:
Client secrets SHOULD NOT be stored in browser local storage.
Perhaps "browser or application"? Clarify what's intended with "local" - specific to localStorage or sessionStorage or using it generally?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the #security-client-secrets section referenced in the issue and review the sentence about client secrets in browser local storage. Determine whether the intended scope is browsers, applications, localStorage, sessionStorage, or local storage generally. Done means the specification wording clearly reflects the intended security guidance.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, documentation
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100